Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit ed6f76b4 authored by Tony Krowiak's avatar Tony Krowiak Committed by Christian Borntraeger
Browse files

KVM: s390/cpacf: Enable key wrapping by default



z/VM and LPAR enable key wrapping by default, lets do the same on KVM.

Signed-off-by: default avatarTony Krowiak <akrowiak@linux.vnet.ibm.com>
Signed-off-by: default avatarChristian Borntraeger <borntraeger@de.ibm.com>
parent c517d838
Loading
Loading
Loading
Loading
+7 −3
Original line number Diff line number Diff line
@@ -839,9 +839,13 @@ static int kvm_s390_crypto_init(struct kvm *kvm)

	kvm_s390_set_crycb_format(kvm);

	/* Disable AES/DEA protected key functions by default */
	kvm->arch.crypto.aes_kw = 0;
	kvm->arch.crypto.dea_kw = 0;
	/* Enable AES/DEA protected key functions by default */
	kvm->arch.crypto.aes_kw = 1;
	kvm->arch.crypto.dea_kw = 1;
	get_random_bytes(kvm->arch.crypto.crycb->aes_wrapping_key_mask,
			 sizeof(kvm->arch.crypto.crycb->aes_wrapping_key_mask));
	get_random_bytes(kvm->arch.crypto.crycb->dea_wrapping_key_mask,
			 sizeof(kvm->arch.crypto.crycb->dea_wrapping_key_mask));

	return 0;
}